Cyber Security Interview Questions Part-2
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…Continue reading on Medium »
Read more...
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…Continue reading on Medium »
Read more...
GCP Inspector | Auditing Publicly Exposed GCP Bucket
Installation of GCP Inspector and basics about enumerating publicly exposed GCP bucket enumeration.Continue reading on Medium »
Read more...
Installation of GCP Inspector and basics about enumerating publicly exposed GCP bucket enumeration.Continue reading on Medium »
Read more...
Doldrums - A Flutter/Dart Reverse Engineering Tool
http://www.kitploit.com/2021/08/doldrums-flutterdart-reverse.html
http://www.kitploit.com/2021/08/doldrums-flutterdart-reverse.html
To flutter: to move in quick, irregular motions, to beat rapidly, to be agitated.
Doldrums: a period of stagnation. Doldrums is a reverse engineering (https://www.kitploit.com/search/label/Reverse%20Engineering) tool for Flutter apps targetting Android. Concretely, it is a parser and information extractor (https://www.kitploit.com/search/label/Extractor) for the Flutter/Dart Android (https://www.kitploit.com/search/label/Android) binary, conventionally named libapp.so, for all Dart version 2.10 releases. When run, it outputs a full dump of all classes present in the isolate snapshot. The tool is currently in beta, and missing some deserialization (https://www.kitploit.com/search/label/Deserialization) routines and class information. If it does not work out-of-the-box, please let me know.
Dependencies
Doldrums requires pyelftools (https://github.com/eliben/pyelftools) to parse the ELF format. You can install it with pip3 install pyelftools
Usage
To use, simply run the following command, substituting libapp.so for the appropriate binary, and output for the desired output file. Note that the verbose option only works for Dart snapshot v2.12. python3 src/main.py [-v] libapp.so output
The expected output is a dump of all classes, in the following format: class MyApp extends StatelessWidget {
Widget build(DynamicType, DynamicType) {
Code at absolute offset: 0xec85c
}
String myPrint(DynamicType, DynamicType) {
Code at absolute offset: 0xeca80
}
}
The absolute code offset indicates the offset into the libapp.so file where the native function may be found.
Reading material
For a detailed write-up on the format, please check my blog post (https://rloura.wordpress.com/2020/12/04/reversing-flutter-for-android-wip/).
Related works
darter (https://github.com/mildsunrise/darter) is a fully implemented and fully tested parser for Dart version 2.5 releases.
Contribute
If you'd like to help the project, consider making a pull request, or donating to ADA: DdzFFzCqrhsgHAVMtnep9Uq9iF61oxZ31LWVG3izmT8BH54Jz7C2gUBFcy6VnCkrbVNqrkevQ4wSwK7dfh7YrUfvSd5toKdE9tzZrcaB BTC: 33piC5kfTdqFyQ5ionmuJkTDJXsFYdzGdS ETH: 0x2bF670503C28B551C80191aeE9F7ACC96e101D9B Logo by Luis Fonseca (https://www.linkedin.com/in/luis-pedro-h-fonseca-4776a024/).
Download Doldrums (https://github.com/rscloura/Doldrums)
Doldrums: a period of stagnation. Doldrums is a reverse engineering (https://www.kitploit.com/search/label/Reverse%20Engineering) tool for Flutter apps targetting Android. Concretely, it is a parser and information extractor (https://www.kitploit.com/search/label/Extractor) for the Flutter/Dart Android (https://www.kitploit.com/search/label/Android) binary, conventionally named libapp.so, for all Dart version 2.10 releases. When run, it outputs a full dump of all classes present in the isolate snapshot. The tool is currently in beta, and missing some deserialization (https://www.kitploit.com/search/label/Deserialization) routines and class information. If it does not work out-of-the-box, please let me know.
Dependencies
Doldrums requires pyelftools (https://github.com/eliben/pyelftools) to parse the ELF format. You can install it with pip3 install pyelftools
Usage
To use, simply run the following command, substituting libapp.so for the appropriate binary, and output for the desired output file. Note that the verbose option only works for Dart snapshot v2.12. python3 src/main.py [-v] libapp.so output
The expected output is a dump of all classes, in the following format: class MyApp extends StatelessWidget {
Widget build(DynamicType, DynamicType) {
Code at absolute offset: 0xec85c
}
String myPrint(DynamicType, DynamicType) {
Code at absolute offset: 0xeca80
}
}
The absolute code offset indicates the offset into the libapp.so file where the native function may be found.
Reading material
For a detailed write-up on the format, please check my blog post (https://rloura.wordpress.com/2020/12/04/reversing-flutter-for-android-wip/).
Related works
darter (https://github.com/mildsunrise/darter) is a fully implemented and fully tested parser for Dart version 2.5 releases.
Contribute
If you'd like to help the project, consider making a pull request, or donating to ADA: DdzFFzCqrhsgHAVMtnep9Uq9iF61oxZ31LWVG3izmT8BH54Jz7C2gUBFcy6VnCkrbVNqrkevQ4wSwK7dfh7YrUfvSd5toKdE9tzZrcaB BTC: 33piC5kfTdqFyQ5ionmuJkTDJXsFYdzGdS ETH: 0x2bF670503C28B551C80191aeE9F7ACC96e101D9B Logo by Luis Fonseca (https://www.linkedin.com/in/luis-pedro-h-fonseca-4776a024/).
Download Doldrums (https://github.com/rscloura/Doldrums)
hacking: security in practice
Cracking a long .zip password with most of the password.
I made a password protected zip file with some sensitive documents and I thought I knew it, but I think I added some characters at the end but forgot about those. The password is long, something like, "Penguins have poor taste," and then there's a special character, maybe a space, and four or five numbers.
I've tried a couple of the commercial products, Passper and PassFab, but their max characters were too short. I was wondering if there was an easy to use product that would fit my needs or if there wasn't, was there a guide for beginners for one of the more complicated methods.
submitted by /u/SocialistSocialWork
[link] [comments]
Cracking a long .zip password with most of the password.
I made a password protected zip file with some sensitive documents and I thought I knew it, but I think I added some characters at the end but forgot about those. The password is long, something like, "Penguins have poor taste," and then there's a special character, maybe a space, and four or five numbers.
I've tried a couple of the commercial products, Passper and PassFab, but their max characters were too short. I was wondering if there was an easy to use product that would fit my needs or if there wasn't, was there a guide for beginners for one of the more complicated methods.
submitted by /u/SocialistSocialWork
[link] [comments]
reddit
Cracking a long .zip password with most of the password.
I made a password protected zip file with some sensitive documents and I thought I knew it, but I think I added some characters at the end but...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Honda/Acura "Unoriginal Rice Patty" FOB Rob Vulnerability
Click here and checkout the FOB Rob vulnerability documentation. Honda and Acura vehicles' wireless FOBs can be permanently robbed in one go!
submitted by /u/HackingInHeart
[link] [comments]
Honda/Acura "Unoriginal Rice Patty" FOB Rob Vulnerability
Click here and checkout the FOB Rob vulnerability documentation. Honda and Acura vehicles' wireless FOBs can be permanently robbed in one go!
submitted by /u/HackingInHeart
[link] [comments]
hacking: security in practice
does a cookie logger seem like the most plausible scenario here?
before context i wanna say that the only possibilites i see here is a somehow a cookie logger or sim swap.
on 03 Aug 1am I received an SMS from my bank that 600eu was attempted to be pulled from my cc through paypal and shortly after they bought 2 copies of a game from a key reseller site which ended up going through. i am thinking they stole the cookies to my outlook email linked to paypal and also to my gmail since there are no login traces and worked their way through paypal with that info. the company from which they made these purchases confirmed that the account was created on the same day using my own gmail account and they also gave me the IP address from where the orders were created from and this is where i think it could have been a sim swap. about a month prior i took my phone for repairs and he had my passcode and all. the IP address was local from an ISP i am aware of (both his and my IPs are static) and the fact that i live in a tiny island it would be a huge coincidence thatthe person who cookie logged me is from the same island. i suppose the same thing could be done if he essentially had a replica of my phone although perhaps less likely. i would like some input from ppl who are more knowledgeable than me especially since the local authorities tried to convince me that i had just clicked on a phishing site or that i was the one who made these purhcases.
submitted by /u/aImondss
[link] [comments]
does a cookie logger seem like the most plausible scenario here?
before context i wanna say that the only possibilites i see here is a somehow a cookie logger or sim swap.
on 03 Aug 1am I received an SMS from my bank that 600eu was attempted to be pulled from my cc through paypal and shortly after they bought 2 copies of a game from a key reseller site which ended up going through. i am thinking they stole the cookies to my outlook email linked to paypal and also to my gmail since there are no login traces and worked their way through paypal with that info. the company from which they made these purchases confirmed that the account was created on the same day using my own gmail account and they also gave me the IP address from where the orders were created from and this is where i think it could have been a sim swap. about a month prior i took my phone for repairs and he had my passcode and all. the IP address was local from an ISP i am aware of (both his and my IPs are static) and the fact that i live in a tiny island it would be a huge coincidence thatthe person who cookie logged me is from the same island. i suppose the same thing could be done if he essentially had a replica of my phone although perhaps less likely. i would like some input from ppl who are more knowledgeable than me especially since the local authorities tried to convince me that i had just clicked on a phishing site or that i was the one who made these purhcases.
submitted by /u/aImondss
[link] [comments]
reddit
does a cookie logger seem like the most plausible scenario here?
before context i wanna say that the only possibilites i see here is a somehow a cookie logger or sim swap. on 03 Aug 1am I received an SMS from...
GCP Inspector | Auditing Publicly Exposed GCP Bucket
https://justm0rph3u5.medium.com/gcp-inspector-auditing-publicly-exposed-gcp-bucket-ac6cad55618c?source=rss------bug_bounty-5
https://justm0rph3u5.medium.com/gcp-inspector-auditing-publicly-exposed-gcp-bucket-ac6cad55618c?source=rss------bug_bounty-5
Installation of GCP Inspector and basics about enumerating publicly exposed GCP bucket enumeration.Continue reading on Medium » (https://justm0rph3u5.medium.com/gcp-inspector-auditing-publicly-exposed-gcp-bucket-ac6cad55618c?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Doldrums - A Flutter/Dart Reverse Engineering Tool
http://3.bp.blogspot.com/-tTUkIW-TdlE/YP8f9froezI/AAAAAAAAops/NJuPvbe9mJwkOax5FX5yTMCcUaQlsPF4ACK4BGAYYCw/w640-h176/Doldrums_1_logo-783659.png
To flutter: to move in quick, irregular motions, to beat rapidly, to be agitated.
Doldrums: a period of stagnation.
Doldrums is a reverse engineering tool for Flutter apps targetting Android. Concretely, it is a parser and information extractor for the Flutter/Dart Android binary, conventionally named
The tool is currently in beta, and missing some deserialization routines and class information. If it does not work out-of-the-box, please let me know.
Dependencies
Doldrums requires pyelftools to parse the ELF format. You can install it with
Usage
To use, simply run the following command, substituting
The expected output is a dump of all classes, in the following format:
The absolute code offset indicates the offset into the
Reading material
For a detailed write-up on the format, please check my blog post.
Related works
darter is a fully implemented and fully tested parser for Dart version 2.5 releases.
Contribute
If you'd like to help the project, consider making a pull request, or donating to
* ADA: DdzFFzCqrhsgHAVMtnep9Uq9iF61oxZ31LWVG3izmT8BH54Jz7C2gUBFcy6VnCkrbVNqrkevQ4wSwK7dfh7YrUfvSd5toKdE9tzZrcaB
* BTC: 33piC5kfTdqFyQ5ionmuJkTDJXsFYdzGdS
* ETH: 0x2bF670503C28B551C80191aeE9F7ACC96e101D9B
Logo by Luis Fonseca.
Download Doldrums
___________________________
@hacking_Attack
@Hacking_Video
Doldrums - A Flutter/Dart Reverse Engineering Tool
http://3.bp.blogspot.com/-tTUkIW-TdlE/YP8f9froezI/AAAAAAAAops/NJuPvbe9mJwkOax5FX5yTMCcUaQlsPF4ACK4BGAYYCw/w640-h176/Doldrums_1_logo-783659.png
To flutter: to move in quick, irregular motions, to beat rapidly, to be agitated.
Doldrums: a period of stagnation.
Doldrums is a reverse engineering tool for Flutter apps targetting Android. Concretely, it is a parser and information extractor for the Flutter/Dart Android binary, conventionally named
libapp.so, for all Dart version 2.10 releases. When run, it outputs a full dump of all classes present in the isolate snapshot.The tool is currently in beta, and missing some deserialization routines and class information. If it does not work out-of-the-box, please let me know.
Dependencies
Doldrums requires pyelftools to parse the ELF format. You can install it with
pip3 install pyelftools
Usage
To use, simply run the following command, substituting
libapp.sofor the appropriate binary, and outputfor the desired output file. Note that the verbose option only works for Dart snapshot v2.12.python3 src/main.py [-v] libapp.so output
The expected output is a dump of all classes, in the following format:
class MyApp extends StatelessWidget {
Widget build(DynamicType, DynamicType) {
Code at absolute offset: 0xec85c
}
String myPrint(DynamicType, DynamicType) {
Code at absolute offset: 0xeca80
}
}
The absolute code offset indicates the offset into the
libapp.sofile where the native function may be found.Reading material
For a detailed write-up on the format, please check my blog post.
Related works
darter is a fully implemented and fully tested parser for Dart version 2.5 releases.
Contribute
If you'd like to help the project, consider making a pull request, or donating to
* ADA: DdzFFzCqrhsgHAVMtnep9Uq9iF61oxZ31LWVG3izmT8BH54Jz7C2gUBFcy6VnCkrbVNqrkevQ4wSwK7dfh7YrUfvSd5toKdE9tzZrcaB
* BTC: 33piC5kfTdqFyQ5ionmuJkTDJXsFYdzGdS
* ETH: 0x2bF670503C28B551C80191aeE9F7ACC96e101D9B
Logo by Luis Fonseca.
Download Doldrums
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Doldrums - A Flutter/Dart Reverse Engineering Tool
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cyber Security Interview Questions Part-2
https://cdn-images-1.medium.com/max/1400/0*gBbKtZQAI2iyYLGG.png
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cyber Security Interview Questions Part-2
https://cdn-images-1.medium.com/max/1400/0*gBbKtZQAI2iyYLGG.png
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Security Interview Questions Part-2
Precontext: This is the part 2 of the series of cyber security interview questions. If you haven’t read the first part go here…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
POPCORN — HackTheBox WriteUp
https://cdn-images-1.medium.com/max/771/1*lLX-zSeXBeaGSsCKlIKYNA.png
This box is a part of TJnull’s list of boxes. I am doing these boxes as a part of my preparation for OSCP. I will be sharing the writeups…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
POPCORN — HackTheBox WriteUp
https://cdn-images-1.medium.com/max/771/1*lLX-zSeXBeaGSsCKlIKYNA.png
This box is a part of TJnull’s list of boxes. I am doing these boxes as a part of my preparation for OSCP. I will be sharing the writeups…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
POPCORN — HackTheBox WriteUp
This box is a part of TJnull’s list of boxes. I am doing these boxes as a part of my preparation for OSCP. I will be sharing the writeups…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HYBRID HACKER SUMMER CAMP 2021 GUIDE — Part Six: DEFCON 29
https://cdn-images-1.medium.com/max/1058/1*I7gZn2LKvXTzyi7W-pMTCw.jpeg
HYBRID HACKER SUMMER CAMP 2021 GUIDE — Part Six: DEFCON 29
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HYBRID HACKER SUMMER CAMP 2021 GUIDE — Part Six: DEFCON 29
https://cdn-images-1.medium.com/max/1058/1*I7gZn2LKvXTzyi7W-pMTCw.jpeg
HYBRID HACKER SUMMER CAMP 2021 GUIDE — Part Six: DEFCON 29
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HYBRID HACKER SUMMER CAMP 2021 GUIDE — Part Six: DEFCON 29
hacking: security in practice
Iphone
My friends father has passed away recently they want us to go to court to be able to get into his iphone 11 pro max. we’re able to get the phone wiped but still has the password for the apple id password, would it be possible for anyone to get into it we’re open to paying we just really need into the phone so get it all erased so we don’t just have a dead iphone.
submitted by /u/_Percaholic_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Iphone
My friends father has passed away recently they want us to go to court to be able to get into his iphone 11 pro max. we’re able to get the phone wiped but still has the password for the apple id password, would it be possible for anyone to get into it we’re open to paying we just really need into the phone so get it all erased so we don’t just have a dead iphone.
submitted by /u/_Percaholic_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Iphone
My friends father has passed away recently they want us to go to court to be able to get into his iphone 11 pro max. we’re able to get the phone...